Seems like a cool initiative, but I'm having trouble understanding what it actually does.
back
1 comments
me to. Screenshots would've helped.
Is it webapp which informs me about new vuln. for my websites (parsing my logfiles)?
That's what the SIEM does, see ones such as IBM QRadar [1]; aggregates all the logs and network flows from across your estate and then uses rules/algorithms to determine threats and security events.
From my limited understanding MozDef is more targeted at ticketing/following through from intelligence gleaned from a SIEM as most times, people then just stick it in Remedy or Jira.
[1] http://public.dhe.ibm.com/common/ssi/ecm/en/wgd03021usen/WGD...
Sorry it's a bit tough to understand. You can think of MozDef as an open source SIEM (taking in logs, parsing, alerting, correlating) plus incident handling workflow with a focus on being open, extensible, visual and realtime. It is early, early days but promising so far!